Hackers Got Inside a Flock Camera
- ID
- 25207
- Status
- summarized
- Published
- 16 Sep 2026, 9:18 PM
- Fetched
- 18 Sep 2026, 9:04 PM
- Provider
- Hacker News
- Category
- dev-community
- Original URL
- https://www.wired.com/story/hackers-flock-camera-data-shows-how-system-works/
- Source URL
- https://hnrss.org/best
Summary
- Score
- 5.5
- Created
- 18 Sep 2026, 10:11 PM
- Tags
- Audience
- developersai_ml_learners
What happened
A hacker collective called stegan0gram physically removed a Flock Safety license plate reader, copied its storage, and recovered an on-device encryption key that unlocked thousands of vehicle detection videos. Analysis of the dumped data revealed the camera captured 1.6 million images of 50,000 vehicles in 21 days and that its computer-vision software explicitly detects people, not just vehicles and plates. The hackers are publishing their methods so others can replicate the reverse engineering.
Why it matters
If you build or deploy edge/IoT devices that store encryption keys on-device, this is a concrete demonstration that physical access defeats on-device encryption—determined attackers pulled the key from the camera's own storage. Builders shipping surveillance or data-collection hardware in Malaysia should assume devices placed in public spaces will be physically tampered with, and should design key management accordingly (e.g., remote attestation, minimal on-device retention) rather than relying on 'encrypted at rest' marketing claims.
Discussion angle
The gap between vendor security claims ('protected by on-device encryption') and what physical access actually yields—useful for anyone evaluating edge device deployments or building hardware that lives in untrusted environments.